Home

Description

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

PUBLISHED Reserved 2025-12-05 | Published 2025-12-09 | Updated 2025-12-09 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

2.4
affected

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab, Semen 'samincube' Rozhkov @zeroscience finder

References

www.exploit-db.com/exploits/50668 (ExploitDB-50668) exploit

www.openbmcs.com (Official Product Homepage) product

www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5692.php (Zero Science Lab Disclosure (ZSL-2022-5692)) third-party-advisory

www.vulncheck.com/.../openbmcs-sql-injection-via-obixtestphp (VulnCheck Advisory: OpenBMCS SQL Injection via obix_test.php) third-party-advisory

cve.org (CVE-2021-47704)

nvd.nist.gov (CVE-2021-47704)

Download JSON